Score breakdown
Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.
Why it matters
Useful for security teams that want one CLI to inventory and audit every MCP server, harness, and agent skill installed on a developer machine, and to flag prompt-injection or data-exfiltration patterns before they leak into production. Install via pip, run `snyk-agent-scan` against a config, and pipe the findings into your existing vulnerability dashboard.
Who should use it
Who should skip it
Pass on snyk/agent-scan if its scope or audience does not match what your team is building right now.
About this signal
snyk/agent-scan is tracked by RepoRadar as a developer tool in the Radar section. First seen 2026-06-17; the source record was last checked on 2026-06-17. The current verdict is 'try now' with a Gold tier and easy setup difficulty. snyk/agent-scan leads on workflow potential (9.9) and novelty (9.0); its lowest signal is evidence quality (7.2), so factor that in before investing setup time. This page summarizes the public evidence on the linked source page and states where additional review is still needed.
How this item is evaluated
The snyk/agent-scan record combines a 8.4/10 composite score with separate popularity (82.0), risk (conditional), and setup (easy) signals. See the scoring methodology for the current weights and evidence definitions.
Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.
Risk explanation
scanning MCP configs will execute the commands they declare — run scans inside a sandbox or disposable environment when evaluating third-party configs; experimental CLI output (severity labels, issue codes, response structure) may change between releases — don't bake field names into production dashboards.